NIST SP 800-53 Rev 5 HIGH
PL: Planning – NIST SP 800-53 Revision 5.1 HIGH

NIST SP 800-53 Rev 5 HIGH PL-8: PL-8 Security and Privacy Architectures

a. Develop security and privacy architectures for the system that: 1. Describe the requirements and approach to be taken for protecting the confidentiality, integrity, and availability of organizational information; 2. Describe the requirements and approach to be taken for processing personally identifiable information to minimize privacy risk to individuals; 3. Describe how the architectures are integrated into and support the enterprise architecture; and 4. Describe any assumptions about, and dependencies on, external systems and services; b. Review and update the architectures [Assignment: organization-defined frequency] to reflect changes in the enterprise architecture; and c. Reflect planned architecture changes in security and privacy plans, Concept of Operations (CONOPS), criticality analysis, organizational procedures, and procurements and acquisitions.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 3 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 1 control

  • PL-8 Security and Privacy Architectures

FedRAMP Moderate · 1 control

  • PL-8 Security and Privacy Architectures

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PL: Planning – NIST SP 800-53 Revision 5.1 HIGH

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.